react-to-review

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional prompts directing the AI to act as a pragmatic software engineer. There is no executable code, script execution, or network communication.
  • [NO_CODE]: No scripts, binaries, or configuration files are included. The analysis is restricted to the natural language instructions provided in the SKILL.md file.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process external code review reports. While this presents a theoretical attack surface for indirect prompt injection, the skill includes structured evaluation steps (Implement, Adapt, Decline) and requires objective justifications, which naturally encourages the agent to treat input as data to be analyzed rather than instructions to be followed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 08:51 PM
Security Audit — agent-trust-hub — react-to-review